Skip to main content
TrustOps
Access

Authentication

OIDC, SAML, and API keys share one tenant, role, and audit boundary — the same identity model as hosted enterprise GRC workspaces.

Server auth
Identity boundaryBrowser SSO + API keys share one tenant and audit model
01IdP sign-inOIDC or SAML with Okta, Entra ID, Google, or generic IdP.
02Map to tenant userVerified email → tenant → role (or API key for headless).
03Issue sessionHttpOnly cookie or API key hash — no parallel auth silo.
04Enforce RBACScopes gate console, connectors, snapshots, and agents.
05Audit every requestActor, tenant, route, decision — same boundary as hosted SSO workspaces.

Login methods

Browser SSO uses your company IdP. API keys serve agents, CI, and MCP clients with the same RBAC envelope.